PatchSiren cyber security CVE debrief
CVE-2025-53696 Johnson Controls CVE debrief
Johnson Controls iSTAR Ultra and Ultra SE door controllers (versions 6.9.2 and prior) contain a firmware verification bypass vulnerability. The devices perform firmware verification on boot, but the verification process does not inspect certain portions of the firmware, allowing those regions to potentially contain malicious code. This vulnerability was published on August 12, 2025, and modified on December 16, 2025, when version 6.9.8 was added as an additional mitigation. The CVSS 3.1 score of 8.8 (High) reflects network attack vector with low attack complexity, low privileges required, and high impacts to confidentiality, integrity, and availability. Firmware version 6.9.3 was made available in 2024 to reduce exploitation risk, with version 6.9.8 recommended for scenarios involving physical access to the door controller. Johnson Controls notes that iSTAR Ultra is an older device with planned end-of-service within a year of publication and recommends upgrading to newer control units. The hardware installation manual requires control units be installed in restricted access, protected areas to reduce physical tampering risk.
- Vendor
- Johnson Controls
- Product
- iSTAR Ultra
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2025-12-16
- Advisory published
- 2025-08-12
- Advisory updated
- 2025-12-16
Who should care
Organizations using Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, or iSTAR Edge G2 door controllers for physical access control. Security teams responsible for building automation and physical security infrastructure. Critical infrastructure operators with integrated physical access control systems. Facilities management teams planning lifecycle replacement of aging door controller hardware.
Technical summary
The iSTAR Ultra and Ultra SE door controllers perform firmware signature verification during the boot process, but the verification implementation is incomplete. Certain firmware regions are excluded from the verification check, creating a gap where attacker-modified code could persist and execute. This affects firmware versions 6.9.2 and prior. The vulnerability requires low privileges to exploit over the network (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), with physical access enabling additional attack vectors. Johnson Controls addressed this through firmware updates that expand verification coverage, with version 6.9.8 providing comprehensive protection including physical access scenarios. The advisory notes this vulnerability is related to CVE-2025-53695, CVE-2025-53697, and CVE-2025-53700, with version 6.9.3 initially addressing the cluster of issues.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade iSTAR Ultra and Ultra SE door controllers to firmware version 6.9.8 to address physical access attack scenarios
- If unable to upgrade immediately, apply firmware version 6.9.3 or newer to reduce exploitation risk
- Install control units in restricted access, protected areas per hardware installation manual requirements to lower physical tampering risk
- Disable Pro Mode and use Ultra Mode on iSTAR Ultra and iSTAR Ultra door controllers
- Implement network segmentation and access controls around iSTAR controllers per Dragos recommendations
- Plan migration to newer control units as iSTAR Ultra approaches end-of-service within one year of advisory publication
- Review Johnson Controls Product Security Advisory JCI-PSA-2025-10 for detailed mitigation instructions
- Contact Johnson Controls Trust Center for assistance with remediation planning
Evidence notes
CISA ICS Advisory ICSA-25-224-02 (Update A) documents that firmware verification on boot does not inspect certain firmware portions, allowing potential malicious code in those regions. Johnson Controls released firmware 6.9.3 in 2024 to address CVE-2025-53695 and reduce risk for this vulnerability. Update A (December 16, 2025) added version 6.9.8 as recommended mitigation for physical access attack scenarios.
Official resources
-
CVE-2025-53696 CVE record
CVE.org
-
CVE-2025-53696 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2025-08-12